Cisco Security Cloud Control: On-Premises Managed Firewall Threat Defense Migration to Cloud Management

PDF

Cisco Security Cloud Control: On-Premises Managed Firewall Threat Defense Migration to Cloud Management

Migration guidelines and limitations for User Identity

Want to summarize with AI?

Log in

Learn how to prepare identity sources before migrating Firewall Threat Defense devices to Cloud-Delivered Firewall Management Center and avoid traffic disruption when access control policies reference identity objects.


Before you migrate an on-premises Firewall Threat Defense to Cloud-Delivered Firewall Management Center, you must prepare and also deploy as soon as possible after the migration if any access control policies reference identity objects discussed in this topic. To confirm, click Policies > Access Control heading > Access Control and examine your access control policies and rules.

If none of your access control policies reference identity objects (in particular, users and groups), you can ignore these guidelines.

Before migrating

Before migrating, on the , click System (system gear icon) > Integration > Identity Sources and see if you have any Cisco ISE/ISE-PIC or Passive Identity Agent identity sources defined.

  • If you have Cisco ISE/ISE-PIC or Passive Identity Agent identity sources defined, create the Cisco ISE/ISE-PIC identity sources on Cloud-Delivered Firewall Management Center then migrate the device as discussed in the following paragraphs.

  • If no Cisco ISE/ISE-PIC or Passive Identity Agent identity sources are defined, migrate the device as discussed in the following paragraphs.

Migrate the device

Migration is discussed in About Firewall Threat Defense migration to Cloud Management. To avoid traffic disruption, when you migrate the device, we strongly recommend you either:

  • Check the Auto deploy to FTDs after successful migration check box.

  • Deploy policies immediately after migration is complete.